NVD disclosure day

Published threat advisories for August 27, 2026

CVE advisoryCRITICAL

CVE-2026-81934

Redis TLS Use-After-Free Vulnerability Allows Remote Command Execution.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A use-after-free vulnerability in Redis, when configured with TLS, may allow a remote, unauthenticated attacker to execute arbitrary commands with the server's privileges. This could lead to unauthorized access and modification of sensitive data.

CVE advisoryCRITICAL

CVE-2026-19092

Tutor LMS WordPress Plugin Arbitrary PHP Function Invocation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the Tutor LMS WordPress plugin that allows unauthenticated users to invoke arbitrary PHP functions and receive their output. This could lead to unauthorized access to sensitive data or system compromise. It is important to identify if this plugin is in use and assess its potential exp

CVE advisoryCRITICAL

CVE-2026-18886

ServiceNow AI Platform Improper Access Control Leading to Privilege Escalation

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An improper access control vulnerability in the ServiceNow AI platform could allow unauthenticated users to modify instance data and escalate privileges. ServiceNow has released a security update, and while exploitation is not currently known, customers should apply updates promptly to mitigate risks.

CVE advisoryCRITICAL

CVE-2026-81826

Flowintel Session Hijacking Vulnerability After Password Reset.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unpatched flaw in Flowintel permits authenticated sessions to persist after a user resets their password. An attacker with a previously compromised session token could maintain unauthorized access until the session expires naturally. This could lead to continued exposure of data or actions accessible through that se

CVE advisoryCRITICAL

CVE-2026-81735

UI-TARS Desktop mcp-http-server Unauthenticated Command Execution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An issue in UI-TARS-desktop's mcp-http-server allows unauthenticated attackers to run arbitrary commands on the server. This is because the server binds to all interfaces by default and authentication is optional. Attackers could execute commands or access file system tools if the vulnerable component is reachable.

CVE advisoryCRITICAL

CVE-2026-81719

openssl_encrypt Plugin Execution Vulnerability Allows Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The `openssl_encrypt` component is vulnerable to arbitrary code execution when an untrusted, unsigned third-party plugin is loaded. This occurs before security controls are fully active, allowing an attacker to run code with the privileges of the user running the application. This is a concern if users can be induced t

CVE advisoryCRITICAL

CVE-2026-81717

openssl-encrypt USB Drive Integrity Bypass and Key Derivation Weaknesses.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The `openssl_encrypt` Python package has weaknesses in its portable USB drive feature, allowing an attacker with physical write access to bypass integrity checks and potentially add malicious files. A predictable encryption key derivation method also enables offline attacks against drives lacking a specific salt file,

CVE advisoryCRITICAL

CVE-2026-81714

OpenSSL Encrypt Plugin Signing Trust Anchor Enrollment Bypass.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in a Python library's plugin-signing process could allow an attacker to enroll a malicious key as a trusted anchor by exploiting a weak identifier comparison. This could lead to malicious plugins being trusted if the ENFORCE signature policy is active. It is uncertain if this specific library function i

CVE advisoryCRITICAL

CVE-2026-81707

OpenSSL Encrypt Identity Document Email ANSI Escape Sequence Injection

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in `openssl_encrypt` allows attackers to inject ANSI escape sequences via the email field of identity documents, potentially forging fingerprint verification displays and bypassing security checks. This manipulation could undermine trust in digital identity verification processes. The vulnerability is r

CVE advisoryCRITICAL

CVE-2026-81706

OpenSSL Encrypt Identity Shadowing Allows Silent Key Substitution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the openssl_encrypt library allows attackers to substitute encryption keys for sensitive files through a flaw in identity and contact management. This could lead to the silent compromise of encrypted data. The exact impact depends on how and where this library is used.

CVE advisoryCRITICAL

CVE-2026-81702

OpenSSL Encrypt Public Key Substitution Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A flaw in an identity management library allows attackers to replace valid public keys with their own, enabling them to intercept encrypted communications and forge signatures that appear legitimate. This could compromise the integrity of digital interactions and undermine trust in cryptographic processes. The vulnerab

CVE advisoryCRITICAL

CVE-2026-81701

openssl_encrypt Arbitrary Code Execution via Unsigned Plugins

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability in `openssl_encrypt` allows unsigned plugins to execute arbitrary code within the CLI process. Attackers can place malicious plugins in specific directories to bypass signature verification, potentially exposing passwords and cryptographic keys. The relevance and exposure of this tool within yo

CVE advisoryCRITICAL

CVE-2026-81698

OpenSSL Encrypt Info Command Shell Injection.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A shell injection vulnerability exists in the `openssl_encrypt` info command when untrusted metadata is interpolated without proper quoting, potentially allowing attackers to inject commands that execute if output is copied into a shell. Uncertainty exists regarding specific products and versions affected, and whether

CVE advisoryCRITICAL

CVE-2026-81696

openssl_encrypt Terminal Control Character Injection Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The `openssl_encrypt` tool's `info` command can be tricked by malicious files containing terminal control characters to display forged verification information. This could mislead users about the authenticity of data they are viewing. The immediate concern is whether this tool and command are actively used within your

CVE advisoryCRITICAL

CVE-2026-81695

openssl_encrypt key_id terminal injection vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in `openssl_encrypt` allows attackers to craft encrypted files containing malicious identifiers that manipulate terminal output. This can lead to forged authenticity verification blocks, potentially misleading users or systems. This issue is relevant for technical readers and security leaders concerned

CVE advisoryCRITICAL

CVE-2026-81694

openssl-encrypt verify-usb command output injection

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the openssl-encrypt package allows crafted filenames on a USB drive to display a false "PASSED" verdict, masking actual tamper detection. This output injection could mislead users about data integrity, though the advisory does not specify affected data. Understanding the package's deployment and data

CVE advisoryCRITICAL

CVE-2026-81685

openssl_encrypt recovery-slot metadata text injection

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the openssl_encrypt desktop GUI allows for the injection of control characters and line separators into file removal confirmation dialogues by crafting encrypted files with malicious metadata, potentially forging warning text to deceive users. This could undermine user trust and lead to accidental da

CVE advisoryCRITICAL

CVE-2026-81681

openssl-encrypt Workspace False Encryption Advisory

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The openssl-encrypt package falsely advertises a portable USB workspace as encrypted, but files placed within it are stored in cleartext. This means an attacker with physical access to the USB media could read sensitive files, despite the branding suggesting they are protected by AES-256-GCM encryption. This poses a ri

CVE advisoryCRITICAL

CVE-2026-81680

openssl_encrypt File Authentication Bypass Via Recovery Slot Removal

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in an encryption tool that allows attackers to remove recovery slots from encrypted files by modifying file headers, bypassing authentication and potentially deleting intended recovery paths. This could impact the integrity and recoverability of sensitive data.

CVE advisoryCRITICAL

CVE-2026-81098

Telnyx MCP Server Missing Authentication on HTTP Transport.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Telnyx MCP server has a vulnerability where its HTTP transport is exposed on all network interfaces without requiring authentication. If reachable, an unauthenticated user could exploit this to gain access to and potentially misuse the server's stored credentials. Confirming the relevance and exposure of this servi

CVE advisoryCRITICAL

CVE-2026-81096

ToolUniverse Python Sandbox Escape Remote Code Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in ToolUniverse's Python code executor, allowing unauthenticated attackers to execute arbitrary code by escaping the sandbox. This is facilitated by insufficient attribute restrictions and default server configurations that expose the tool externally without authentication. The attacker

CVE advisoryCRITICAL

CVE-2026-81094

MCP Router CLI Default Open Aggregator Exposure

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the mcp-router CLI could expose its aggregator service to unauthorized access by defaulting to all network interfaces without authentication. This allows anyone reaching the exposed port to interact with the aggregator and any MCP servers it fronts. This risk is present when the CLI is invoked withou

CVE advisoryCRITICAL

CVE-2026-78251

DJI Drone FTP Storage Exhaustion Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

DJI drones have an FTP service that allows unauthorized users with internal network or USB access to upload unlimited files, potentially filling the drone's storage. This can prevent the recording of flight records, logs, and telemetry, and may interfere with firmware updates. The uploaded files persist across reboots

CVE advisoryCRITICAL

CVE-2026-57499

Liman OS Command Injection via Log Rotation Configuration

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An OS command injection vulnerability exists in Liman server management software that allows an authenticated administrator to execute arbitrary commands. The issue stems from improper sanitization of the `ip_address` parameter within the log rotation configuration, enabling an attacker to perform shell escape. This co

CVE advisoryCRITICAL

CVE-2026-16279

3DEXPERIENCE 3DPassport Improper Authorization Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An Improper Authorization vulnerability in 3DPassport for 3DSwymer could allow an attacker to gain access to some user accounts. This issue is reachable via the network and may require user interaction with malicious content. Confirmation of affected deployments is needed to understand potential impact.

CVE advisoryCRITICAL

CVE-2026-81675

SQL Injection in isquad /ws/apiprensa/getVideoUltimasSeccion Endpoint Leads to Database Errors

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability in a web application's video content retrieval endpoint allows attackers to disrupt database queries by manipulating a parameter, potentially exposing internal query logic. This could affect how content is retrieved if the endpoint is reachable. It is important to verify if this technology

CVE advisoryCRITICAL

CVE-2026-81674

SQL Injection in API Endpoint Exposes Database Details.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability exists in a web application API endpoint that processes requests via the `id_ambito` parameter. Attackers can exploit this by sending unsanitized input directly into a MariaDB query, which could lead to the exposure of database error messages and internal query structures, potenti

CVE advisoryCRITICAL

CVE-2026-81673

SQL Injection in isquad API Tribuna Endpoint

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in a web application endpoint that allows remote attackers to manipulate visit tracking records and disrupt database operations. This could compromise the integrity of analytics and the accuracy of recorded data. The primary concern is determining the relevance and exposure of this

CVE advisoryCRITICAL

CVE-2026-81672

SQL Injection in getVideoSubcanal Endpoint Exposes File Paths and Stack Traces

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in an application's API endpoint due to improper handling of the `id_video` parameter. This flaw could allow unauthorized individuals to inject malicious SQL commands, potentially exposing internal file paths and stack traces. The vulnerability is reachable via the network without a

CVE advisoryCRITICAL

CVE-2026-74233

Zbtlink Firmware Command Injection via UDP/9992

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical command injection vulnerability exists in Zbtlink firmware that allows unauthenticated remote attackers to execute arbitrary commands as root via specially crafted UDP packets. The exploitable infosrvd service uses an ineffective authentication mechanism, rendering it vulnerable to bypass. This could lead to

CVE advisoryCRITICAL

CVE-2026-74232

Zbtlink and MoreQuick Devices Vulnerable to Remote Command Execution via Backdoor Implant.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A backdoor implant in firmware for certain Zbtlink and MoreQuick networking devices allows unauthenticated remote attackers to execute arbitrary commands, modify DNS settings, and exfiltrate credentials over an unencrypted UDP channel. This could lead to a full system compromise and data theft.

CVE advisoryCRITICAL

CVE-2026-78292

Hash Form PHP Object Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical PHP Object Injection vulnerability exists in the Hash Form WordPress plugin, potentially allowing unauthenticated attackers to execute arbitrary code on affected systems. This issue poses a risk to system confidentiality, integrity, and availability if the plugin is internet-facing.

CVE advisoryCRITICAL

CVE-2026-78288

Beautiful Taxonomy Filters SQL Injection <= 2.4.6

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the Beautiful Taxonomy Filters WordPress plugin. This flaw could allow attackers to access or modify database content without authentication. The risk is heightened as this plugin is part of web applications, potentially exposing sensitive data.

CVE advisoryCRITICAL

CVE-2026-78286

Geo Controller PHP Object Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated PHP Object Injection vulnerability exists in the Geo Controller. If reachable, an attacker could inject malicious PHP objects to execute arbitrary code, potentially leading to a complete system compromise. Confirming relevance and exposure is crucial.

CVE advisoryCRITICAL

CVE-2026-78274

Fluent Boards Pro Arbitrary File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Fluent Boards Pro, a web application plugin, contains a critical arbitrary file upload vulnerability. If reachable by an authenticated administrator, this could allow unauthorized file uploads, potentially leading to code execution and impact to system integrity and availability. Confirming the use of this plugin is ne

CVE advisoryCRITICAL

CVE-2026-78260

Epayco Plugin SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in Epayco software, potentially allowing attackers to manipulate database queries and gain unauthorized access to sensitive data. Organizations using Epayco should verify its presence and assess potential exposure, as such flaws can impact systems handling sensitive

CVE advisoryCRITICAL

CVE-2026-59354

Spring Security OAuth2 Authorization Server Dynamic Client Registration Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Spring Security's OAuth2 Authorization Server has a vulnerability in its Dynamic Client Registration feature when enabled, allowing an attacker with an initial access token to register a malicious client using crafted metadata. This insufficient validation could lead to stored cross-site scripting, privilege escalation

CVE advisoryCRITICAL

CVE-2026-32566

ACPT Pro Privilege Escalation Vulnerability in WordPress Plugin

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated privilege escalation vulnerability exists in a WordPress plugin, potentially allowing unauthorized users to gain administrative control of affected websites. This could lead to modifications of site content and settings if the plugin is actively used and reachable.

CVE advisoryCRITICAL

CVE-2026-32479

Visitor Traffic Real Time Statistics Pro Unauthenticated SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in Visitor Traffic Real Time Statistics Pro, potentially allowing attackers to access or manipulate sensitive data. This could lead to data exposure or service disruption if the affected plugin is in use and reachable.

CVE advisoryCRITICAL

CVE-2026-77991

Joomla Event Manager Remote Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Joomla Event Manager allows an administrator to upload dangerous file types, potentially leading to remote code execution. This could result in unauthorized control over the affected system. The main concern is to determine if this extension is used within the environment.

CVE advisoryCRITICAL

CVE-2026-77016

Workeera WordPress Plugin Arbitrary File Deletion Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Workeera WordPress plugin contains a vulnerability that allows authenticated users with subscriber privileges to delete arbitrary files from the server, potentially impacting system integrity and availability. This issue is relevant because WordPress plugins are often part of internet-accessible applications.

CVE advisoryCRITICAL

CVE-2026-59270

Spring Security UnboundID LDAP Server Registration Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Spring Security's embedded UnboundID LDAP server can be reached over the network, potentially exposing administrative credentials due to unconditional registration and binding to all interfaces. This could allow unauthenticated access to sensitive data. Uncertainty exists regarding the exploitability as the LDAP server

CVE advisoryCRITICAL

CVE-2026-47891

Spring WebFlux XML Parsing Vulnerability Affects Max Size Limit.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Spring WebFlux applications using the Aalto XML processor allows for resource exhaustion when parsing XML input due to an improperly enforced memory size limit. This could affect application availability and lead to denial-of-service conditions. The issue has a high potential for external exploitatio

CVE advisoryCRITICAL

CVE-2026-47890

Spring MVC and WebFlux Stream Corruption Vulnerability with Server-Sent Events.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Spring MVC and WebFlux applications face stream corruption risks when using Server-Sent Events with view fragments. Attackers could potentially exploit this to corrupt data streams, impacting application data integrity and leading to unpredictable behavior.

CVE advisoryCRITICAL

CVE-2026-47884

Spring MVC SSRF and RCE Vulnerability with XsltView

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Spring MVC applications that use XsltView without an explicitly defined view name and a catch-all mapping. This configuration could allow an attacker to exploit the application, potentially leading to server-side request forgery or remote code execution. This issue is relevant to appl